PHP Remote File Inclusion Vulnerability in DFDevelopment Ronneby Theme Core
CVE-2025-63036
7.5HIGH
What is CVE-2025-63036?
The DFDevelopment Ronneby Theme Core contains a vulnerability that allows for PHP Local File Inclusion due to improper control of the filename for include or require statements. This flaw can expose sensitive files on the server and can be exploited by attackers to execute arbitrary code or access confidential information. The affected versions of the Ronneby Theme Core extend from not applicable up to and including version 1.5.68, making it imperative for users to update their installations to mitigate potential risks.
Affected Version(s)
Ronneby Theme Core <= n/a
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program